So What Club
Start free
Cybersecurity
Lesson 2 of 3 Math checked Facts checked against sources on 30 September 2026 11 min

Cybersecurity economics: breach risk, SaaS and services

Weigh a security investment against expected breach losses, run the numbers of a security software company, and see why around-the-clock monitoring favours scale.

Industry brief, with a one-minute summary: Cybersecurity

Firm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.

Key takeaways

  • A buyer judges security like insurance: how much does this cut the expected cost of breaches, and is that more than it costs?
  • Customers run many separate security tools, each with its own contract, console and alerts.
  • Expected loss is the chance of an event in a year multiplied by what it would cost.

Key idea

A buyer judges security like insurance: how much does this cut the expected cost of breaches, and is that more than it costs? A seller is usually a subscription software business, where retention, expansion and gross margin decide the value.

Expected loss is the chance of an event in a year multiplied by what it would cost. It is a rough tool, because the chance is hard to know, but it turns a scary topic into a business decision. The cost of a breach includes stopped operations, recovery work, lost customers, legal and regulatory costs, and sometimes a ransom. IBM's 2026 study puts the average at about USD 4.99 million worldwide, about USD 11.5 million in the US and about USD 8 million in the Middle East (as reported), with large differences by industry and company size.

Worked case

Is a security upgrade worth it for a logistics company in Dubai?

The prompt

A logistics company in Dubai reports in USD. Its security team estimates an 8 percent chance each year of a major ransomware attack that would stop operations, costing about USD 6 million. A package of controls (endpoint detection, multi-factor login for all staff, and offline backups) costs USD 200,000 a year. The team estimates it cuts the chance to 3 percent a year and, because recovery is faster, cuts the cost of an attack to USD 4 million. Is the package worth it on expected loss? (Figures are illustrative.)

Open this case to practice it with a partner

The structure

  • Net benefit = drop in expected loss minus the cost of the controls
    • Expected loss = probability a year x cost of an attack
    • Compare before and after the controls
    • Subtract the yearly cost of the controls

Working it through

  1. 1. Expected loss today

    8 percent of USD 6 million, in USD millions.

    Expected loss today (USD millions a year):0.08 × 6 = 0.48
  2. 2. Expected loss with the controls

    3 percent of USD 4 million.

    Expected loss with controls (USD millions a year):0.03 × 4 = 0.12
  3. 3. Drop in expected loss

    0.48 minus 0.12.

    Drop in expected loss (USD millions a year):0.08 × 6 - 0.03 × 4 = 0.36
  4. 4. Net benefit

    The drop minus USD 0.2 million of yearly cost.

    Net benefit a year (USD millions):0.08 × 6 - 0.03 × 4 - 0.2 = 0.16

The recommendation

The company should buy the package, because it lowers expected losses by about USD 360,000 a year for USD 200,000, a net benefit of about USD 160,000 a year. First, most of the gain comes from making an attack less likely, from 8 to 3 percent. Second, faster recovery also matters: cutting the cost of an attack from USD 6 million to USD 4 million protects the business if an attack gets through anyway. The risk is that the probabilities are rough estimates; the case still holds if the true chance today is 6 percent rather than 8, but not much lower, because below about 5.3 percent the drop in expected loss no longer covers the cost. As a next step, check what the company's cyber insurer requires, since these controls may also lower the premium.

Risks: Probabilities are estimates and could be far off; Controls only work if staff use them and backups are tested; A single attack can cost much more than the average.

Worked case

ARR bridge of a cloud security vendor in Bengaluru

The prompt

A cloud security software company in Bengaluru sells worldwide and reports in USD. It starts the year with USD 40 million of ARR (annual recurring revenue). It wins USD 12 million of new ARR, existing customers add USD 8 million by protecting more cloud accounts and buying new modules, and it loses USD 2 million to churn and downgrades. It spent USD 14.4 million on sales and marketing to win the new customers, and its gross margin is 80 percent. Calculate ending ARR, growth, net and gross revenue retention, and CAC payback. (Figures are illustrative.)

Open this case to practice it with a partner

The structure

  • Security SaaS health check
    • ARR bridge: start + new + expansion minus churn = end
    • NRR = (start + expansion minus churn) / start; GRR = (start minus churn) / start
    • CAC payback = acquisition spend / (new ARR x gross margin), in months

Working it through

  1. 1. Ending ARR

    40 plus 12 plus 8 minus 2.

    Ending ARR (USD millions):40 + 12 + 8 - 2 = 58
  2. 2. ARR growth

    Increase of 18 on a start of 40.

    ARR growth (percent):(58 - 40) ÷ 40 × 100 = 45
  3. 3. Net revenue retention

    Existing customers only: 40 plus 8 minus 2, divided by 40.

    NRR (percent):(40 + 8 - 2) ÷ 40 × 100 = 115
  4. 4. Gross revenue retention

    Without expansion: 40 minus 2, divided by 40.

    GRR (percent):(40 - 2) ÷ 40 × 100 = 95
  5. 5. CAC payback

    New ARR of 12 brings 9.6 of gross profit a year, 0.8 a month. Spend of 14.4 is repaid in 18 months.

    CAC payback (months):14.4 ÷ (12 × 0.8) × 12 = 18

The recommendation

The company is healthy and should keep investing in selling more modules to existing customers, because it grows 45 percent with net revenue retention of 115 percent and pays back acquisition spend in 18 months. First, USD 8 million of expansion is two thirds as large as new-customer ARR, and it costs far less to win. Second, gross retention of 95 percent shows customers rarely leave, which is typical of security tools that are hard to switch off once installed. The risk is that large platform vendors bundle a similar product for free, which would slow new wins. As a next step, track which modules existing customers add, and price the most-used ones as a bundle.

Risks: Platform vendors may bundle a similar product into existing contracts; Rupee costs against dollar revenue move margins; A breach at the vendor itself would damage trust quickly.

Timed math drill

A company wants three analysts watching its systems at all times, every hour of the week. Each analyst works 40 hours a week. Ignoring holidays and sick leave, how many analysts must it employ?

Platform versus best of breed

Customers run many separate security tools, each with its own contract, console and alerts. Large vendors now sell a platform: several categories under one contract, often with a discount, and argue that shared data catches more attacks. Specialist vendors argue their single product is better at its job. For a vendor, the platform raises spend per customer and makes it harder to leave; for a buyer it lowers cost and complexity but increases dependence on one supplier, as the July 2024 outage caused by a faulty CrowdStrike update showed: Microsoft estimated 8.5 million Windows devices were affected.

Timed math drill

A bank in Singapore pays for six separate security tools at SGD 150,000 each a year. A platform vendor offers to replace all six for 25 percent less in total. How much does the bank save a year, in SGD?

Check your understanding

Why do security software companies often have high gross retention?

Sources for this lesson (3)
My notes on this lesson

0 of 5,000 characters. Saves automatically.

Try the 3 remaining checks and drills above to complete this lesson (0 of 3 done).

Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.